CVE Vulnerabilities

CVE-2021-22267

Authentication Bypass by Capture-replay

Published: Feb 09, 2021 | Modified: Feb 26, 2021
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^AAF, T0665L01^AAP, and T0662L01^AAP (L) and T0320H01^ABO through T0320H01^ABY, T0952H01^AAG through T0952H01^AAQ, T0986H01 through T0986H01^AAE, T0665H01^AAO, and T0662H01^AAO (J and H).

Weakness

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Affected Software

Name Vendor Start Version End Version
Web_viewpoint Hpe 06.03 (including) 06.23.01 (including)
Web_viewpoint Hpe 15.08.00 (including) 19.08.00 (including)
Web_viewpoint Hpe t0320h01^abw (including) t0320h01^acc (including)
Web_viewpoint Hpe t0952h01^aaq (including) t0952h01^aaw (including)
Web_viewpoint Hpe t0952l01^aar (including) t0952l01^aax (including)
Web_viewpoint Hpe t0986h01^aac (including) t0986h01^aai (including)
Web_viewpoint Hpe t0986l01^aad (including) t0986l01^aaj (including)
Web_viewpoint Hpe 15.02.00 (including) 15.02.00 (including)
Web_viewpoint Hpe 15.02.01 (including) 15.02.01 (including)
Web_viewpoint Hpe t0320l01^aby (including) t0320l01^aby (including)
Web_viewpoint Hpe t0320l01^acd (including) t0320l01^acd (including)

Potential Mitigations

References